﻿using System;
using System.Collections.Generic;
using System.Data;
using System.Data.SqlClient;
using System.Web.Configuration;
using System.Web;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.Security;

namespace comix
{
    public partial class pubadmin : System.Web.UI.Page
    {
        protected void Page_Load(object sender, EventArgs e)
        {
            err.Visible = Request.QueryString["er"] != null;
        }

        protected void Button1_Command(object sender, CommandEventArgs e)
        {            
            if (TextBox1.Text == "admin" && TextBox2.Text == "admin")
            {
                string s = FormsAuthentication.GetRedirectUrl("admin", false);
                Session["user"] = -1;
                if (s == "/d")
                {
                    FormsAuthentication.SetAuthCookie("admin", false);
                    Response.Redirect("admininstration/books.aspx");
                }
                else
                    FormsAuthentication.RedirectFromLoginPage("admin", false);
                
                
            }
            else
            {
                SqlConnection con = new SqlConnection(WebConfigurationManager.ConnectionStrings["mainconectionstring"].ConnectionString);
                SqlCommand com = new SqlCommand();
                com.Connection = con;
                com.CommandText = "SELECT ISNULL(pub_id,-1) FROM PUBLISHERS WHERE pub_username = @pub_username AND pub_password = @pub_password";
                com.Parameters.Add(new SqlParameter("@pub_username", TextBox1.Text));
                com.Parameters.Add(new SqlParameter("@pub_password", TextBox2.Text));
                con.Open();
                int pubid = Convert.ToInt32(com.ExecuteScalar());
                con.Close();
                if (pubid > 0)
                {
                    Session["user"] = pubid;
                    string s = FormsAuthentication.GetRedirectUrl("publisher", false);
                    if (s == "/d")
                    {
                        FormsAuthentication.SetAuthCookie("publisher", false);
                        Response.Redirect("pubadministration/sales.aspx");
                    }
                    else
                        FormsAuthentication.RedirectFromLoginPage("publisher", false);                    
                }
                else
                    Response.Redirect("pubadmin.aspx?er=1");
            }
        }
    }
}
